EU AI ActArt. 99

Penalties and enforcement: what €35M / 7% actually means for a mid-sized company

"Up to €35 million or 7% of global turnover" is the number everyone quotes about the AI Act. It's real, but the headline hides what actually matters to a mid-sized company — which tier applies to which breach, and why the percentage, not the euro figure, is usually the frightening part. Let's read it honestly.

The three tiers

Article 99 sets penalties in bands, and they track how serious the breach is. The top band — up to €35 million or 7% of worldwide annual turnover, whichever is higher — is reserved for breaching the prohibited-practice rules. Most other obligation breaches (the high-risk and transparency duties) sit in a middle band of up to €15 million or 3%. Supplying incorrect, incomplete or misleading information to authorities carries up to €7.5 million or 1%. The fine scales with the gravity of what you did, not randomly.

Why the percentage is the real story

For a large multinational the euro caps bite; for a mid-sized company, the percentage is usually the more alarming number, because a few per cent of turnover can dwarf a fixed figure relative to your margins. That's the point of a turnover-based penalty: it's designed to be felt at any size. It also means "we're too small to be a target" is a weak comfort — the penalty is proportionate by design.

Proportionality and SMEs

The Act does build in proportionality. Fines are meant to be effective, proportionate and dissuasive, and authorities take into account the nature of the breach, whether it was intentional, steps taken to mitigate, and the size of the operator — with specific attention to SMEs. This is not a loophole, but it does mean that a company which acted in good faith, documented its diligence and moved quickly to fix problems is in a very different position from one that ignored the rules.

How enforcement actually lands

Enforcement runs through the AI Office at EU level and national market-surveillance authorities. In practice, early enforcement tends to focus on the clearest, most harmful breaches — prohibited practices and blatant transparency failures — rather than good-faith companies with imperfect paperwork. The durable protection isn't hoping to stay invisible; it's being able to show, on demand, that you classified your systems, met the obligations that applied, and kept evidence.

The honest conclusion

The penalties are large enough to justify acting, and the dates are set by law, not by anyone's marketing. But the response isn't panic — it's diligence you can prove. A company that knows its role, its risk tier, and its obligations, and has the evidence to show it, has converted a scary headline into a managed risk. That's the whole game.

The bottom line. The €35M / 7% headline is real, but for a mid-sized company the percentage and the proportionality rules are what matter. Documented, good-faith diligence is both the cheapest insurance and the strongest defence — and it's entirely within your control.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your obligations, consult qualified counsel.